CVE-2021-36296: OS Command Injection
Published Jan 25, 2022
·Updated
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.
Affected Software
9 affected components
Dell EMC Unity Operating Environment<=8.1.21.266
Dell Vnx Vg10
Dell Vnx Vg50
Dell Vnx5200
Dell Vnx5400
Dell Vnx5600
Dell Vnx5800
Dell Vnx7600
Dell Vnx8000
Event History
Jan 25, 2022
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36296?
CVE-2021-36296 is considered a critical vulnerability due to its potential for authenticated remote code execution.
2
How do I fix CVE-2021-36296?
To fix CVE-2021-36296, users should upgrade to a version of Dell VNX2 OE for File later than 8.1.21.266.
3
Who is affected by CVE-2021-36296?
CVE-2021-36296 affects users of Dell VNX2 OE for File versions 8.1.21.266 and earlier.
4
What are the consequences of exploiting CVE-2021-36296?
Exploiting CVE-2021-36296 allows a remote malicious user to execute commands on the system with privileges.
5
Is Dell VNX2 OE for File still vulnerable after the update?
No, updating to a version later than 8.1.21.266 will mitigate the vulnerability identified in CVE-2021-36296.